Back to Feed
Nation-stateOct 8, 2026

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

China-linked hackers stole emails and provided third-party access via a portal.

Summary

Hackers associated with the China-based Integrity Technology Group have been stealing emails from government, law enforcement, healthcare, and religious organizations across Southeast Asia, Africa, and North America since at least January 2021. The group also operated a portal to provide third-party access to the stolen data. The U.S. and UK have sanctioned Integrity Technology Group, and the FBI disrupted a botnet controlled by the company in 2024.

Full text

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails Swati KhandelwalOct 08, 2026Data Breach / Cyber Espionage Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other countries said on October 8. The company, Integrity Technology Group, has been sanctioned by the U.S. and the UK. The hackers scanned websites for flaws using a tool containing more than 1,300 scripts, guessed passwords for Microsoft 365 and Exchange accounts, and copied mailboxes using tools designed to collect mail. The hackers have been breaking into networks since at least mid-January 2021, according to the agencies' joint advisory. It describes the hacking in the present tense but provides no date for any theft and does not specify how many organizations were breached. The same hackers targeted U.S. government services, critical manufacturing, healthcare, and IT organizations, along with U.S. law enforcement, education, and religious groups. Organizations in Southeast Asia, Africa, and North America were also targeted. The hackers also run a web application that "provides third-party access to stolen email content," the advisory said. It does not identify those third parties. In September 2024, the FBI disrupted a botnet, a network of hijacked devices, that the U.S. Justice Department said Integrity Technology Group controlled. It held more than 200,000 routers, cameras, and other consumer devices, and Lumen researchers had named it Raptor Train. The 2024 action dealt with the botnet. The new advisory covers how the hackers get into networks and what they take. It is based on evidence the FBI recovered and observed during several investigations related to the company. Who Is Behind It The agencies describe Integrity Technology Group as "a China-based for-profit company with links to the Chinese government" whose employees build or get cyber tools "for use and sale," host infrastructure, and break into networks. The advisory uses a single label, "the threat actors," for the company and the hackers it enables. It does not say which of them carried out each break-in. The U.S. Treasury sanctioned the company in January 2025 for its role in several computer break-ins against U.S. victims. The UK sanctioned it in December 2025. Christopher Wray, then the FBI director, said in 2024 that the company's "chairman has publicly admitted that for years his company has collected intelligence and performed reconnaissance for Chinese government security agencies." The hackers' methods are "consistent with" activity that security companies track as Flax Typhoon, Ethereal Panda, and RedJuliett, among others, the advisory said. Those names may not match the U.S. government's own tracking one-to-one, and the same hackers may also carry out work unrelated to Integrity Technology Group. Flax Typhoon is Microsoft's name for a China-based group that it described in 2023 as targeting organizations in Taiwan. Integrity Technology Group rejected the U.S. accusations in January 2025. It told the Shanghai Stock Exchange that the U.S. move had no factual basis, the Associated Press reported. A Chinese Foreign Ministry spokesperson, asked about the sanctions, said China firmly opposed the U.S. action, according to the same report. How the Hackers Get In The hackers look for flaws in networks and web applications with open-source scanners such as Nmap, masscan, and WPScan, the advisory said. Their scans focus on ports 21, 22, 53, 80, 443, and 1080. "The use of open source tools typically found on GitHub suggests the threat actors tend to look for more vulnerable targets," the agencies said. The hackers have also used a scanner called MicroScan since as early as 2017. It is a Python web application containing more than 1,300 penetration testing scripts designed to scan websites for specific flaws. The hackers have used the scripts against services including OpenSSL, Oracle WebLogic Server, Rejetto HFS, WordPress, Juniper ScreenOS, Jenkins, and Apache Struts. The UK's National Cyber Security Centre, one of the agencies behind the advisory, said in its news release that the hackers are "uniquely using AI tools, such as automated scanning." The advisory itself does not mention AI. The hackers mostly get in with command-line tools built on exploit code written in languages such as Python and Go. The advisory lists 8 known flaws that it says were successfully exploited. The flaws were found in the hackers' penetration testing scripts. The table shows the affected versions as the advisory gives them and, where one could be confirmed, the release that fixes the flaw. Flaw Product Affected Versions in the Advisory Fixed In CVE-2014-6278 GNU Bash Through 4.3 bash43-026 Not confirmed CVE-2015-3306* ProFTPD 1.3.5 1.3.5a CVE-2015-5477* ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 9.9.7-P2 or 9.10.2-P3 CVE-2016-3081* Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28 2.3.20.3, 2.3.24.3, or 2.3.28.1 CVE-2019-11510 Pulse Connect Secure 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 8.2R12.1, 8.3R7.1, or 9.0R3.4, from the advisory's ranges CVE-2021-22205 GitLab All versions starting from 11.9 13.8.8, 13.9.6, or 13.10.3, per its NVD record CVE-2021-3199* ONLYOFFICE Document Server 5.1.5 through 5.6.2 5.6.3 CVE-2023-22894* Strapi Up to 4.5.5 4.8.0 The advisory marks 5 of the 8 with an asterisk and describes them as newly added to the Known Exploited Vulnerabilities (KEV) catalog, the list of flaws that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) says have been used in attacks. They were not in the catalog data that CISA publishes on GitHub (version 2026.10.04) when The Hacker News checked at 18:05 UTC on October 8. Strapi's own advisory gives a wider range than the joint advisory. It says versions from 3.2.1 through 4.7.9, but not including 4.8.0, are affected. Two flaws depend on a setting. The Struts flaw works only when Dynamic Method Invocation is turned on, and Apache says turning it off is an alternative to upgrading. The ONLYOFFICE flaw applies when JWT is used, according to its NVD record. The BIND flaw is a denial-of-service bug that makes the DNS server exit. Another way in is a fake login. The FBI recovered a cross-site scripting (XSS) payload that changes a vulnerable web page to show username and password fields. After a visitor enters any username and password, the page offers a password-protected ZIP file that holds a program named live700_v1.exe. That program starts a process named DiagTrack.exe, the same name as a legitimate Windows program, which sends encrypted traffic to dns.studiocloud[.]xyz. The FBI attributes that domain to Integrity Technology Group and assesses that the malware likely targets email. The hackers also use password spraying, which means trying a few common passwords against many accounts. For this, they use EBurst, an open-source Python tool that targets Microsoft 365 and Exchange accounts. EBurst tries logins through Exchange interfaces that include ECP, EWS, OAB, OWA, RPC, API, MAPI, PowerShell, Autodiscover, and Microsoft-Server-ActiveSync, according to its README file. Defenders should cover these interfaces, the agencies said. How They Stay and What They Take To keep access, the hackers install SoftEther, a legitimate VPN program that security software is less likely to flag, the advisory said. They often rename the installer conhost.exe or dllhost.exe so it looks like a Windows file, and they set the client to reconnect each time the machine starts. To take credentials, they ran a tool named DC.exe that uses DCSync, a technique that copies data from a domain controller through Active Directory's replication service. It copied account credentials, group membership details, and trust relationships. For email, the hackers bui

Indicators of Compromise

  • mitre_attack — T1071
  • mitre_attack — T1110
  • mitre_attack — T1041

Entities

Flax Typhoon (threat_actor)Ethereal Panda (threat_actor)RedJuliett (threat_actor)Microsoft (vendor)Microsoft 365 (product)Integrity Technology Group (vendor)